CRITICAL

CVE-2026-90605

2026-09-14 CVSS v3.1
CVSS
9.9

Description

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

Weakness (CWE)

CWE-119 Memory Buffer Bounds Error
CWE-120 Classic Buffer Overflow

EPSS Score

0.47%
Probability of exploitation in next 30 days
39.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE